Module 1 of the free EU AI Act Fundamentals course: what counts as an AI system under Art. 3(1), who the Act binds, extraterritorial reach, and the exclusions people miss.
The AI Act is the first horizontal AI regulation anywhere. "Horizontal" is the word that matters: it does not regulate a sector, it regulates a technology and the use it is put to. That is why a bank, a hospital and a recruitment agency can all be in scope for entirely different reasons — and why a bank can be in scope as an employer while its trading desk stays out.
This module answers three questions: what counts as an AI system, who the Act binds, and what it leaves alone.
What counts as an AI system
Art. 3(1) defines an AI system as a machine-based system that, with varying levels of autonomy and possible adaptiveness after deployment, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
The load-bearing word is infers. It draws the line that most scoping exercises get wrong in both directions:
- A model that learned a mapping from data — a classifier, a scoring model, a language model, a recommender — infers. It is in.
- A deterministic rules engine that executes conditions a human wrote — "if balance < 0 and days > 30 then flag" — does not infer. The Commission's guidelines on the definition of an AI system (February 2025) say so explicitly: simple rule-based systems fall outside.
That distinction is worth money. Firms routinely declare their whole decision-engine estate as "AI" and then spend a year documenting rule sets that were never in scope. Others do the reverse and quietly exclude a scoring model because "it's just statistics" — statistical learning is squarely inside the definition.
Being an AI system is only step one. It makes the Act applicable; it says nothing yet about how much of the Act applies. That is risk classification, and it is Module 2.
Who the Act binds
The Act assigns obligations by role, not by industry. Four roles carry duties:
| Role | Who you are | Weight of obligation |
|---|---|---|
| Provider | You develop an AI system, or have it developed, and place it on the market or put it into service under your own name or trademark | Heaviest — the full Art. 8–17 set for high-risk |
| Deployer | You use an AI system under your own authority, in a professional capacity | Lighter but real — Art. 26, and Art. 27 for some public-interest bodies |
| Importer | You are established in the EU and place on the market a system from a third-country provider | Verification duties, Art. 23 |
| Distributor | You are in the supply chain and make a system available, without being provider or importer | Verification duties, Art. 24 |
Most financial entities assume they are deployers, and most of the time they are right. But Art. 25 turns a deployer into a provider in three situations, and every one of them is a normal commercial decision somebody makes without calling a lawyer:
- You put your own name or trademark on a high-risk system already on the market.
- You make a substantial modification to a high-risk system that is already on the market.
- You change the intended purpose of a system — including a non-high-risk one — such that it becomes high-risk.
Buying a vendor model, white-labelling it in your app and pointing it at a use case the vendor never described is enough to make you the provider, with the full obligation set and the vendor's cooperation duty as your only lifeline (Art. 25(4)). This is the single most expensive mistake in AI Act scoping.
Extraterritorial reach
Art. 2(1) does not ask where you are established. It catches:
- providers who place on the EU market or put into service an AI system in the EU, wherever they are established;
- deployers who have their place of establishment or are located in the EU;
- and — the one that surprises people — providers and deployers in a third country where the output produced by the system is used in the EU.
A model trained and hosted in São Paulo, run by a Brazilian company, whose scores are used to decide on EU customers, is in scope. Geography of infrastructure is irrelevant; geography of effect is what counts.
What the Act leaves alone
Scope has real edges, and they are worth knowing before you inventory anything:
- Military, defence and national security purposes are excluded entirely (Art. 2(3)).
- Scientific research and development — systems developed and put into service for the sole purpose of scientific research (Art. 2(6)).
- Pre-market R&D activity: research, testing and development before a system is placed on the market, except testing in real-world conditions (Art. 2(8)).
- Personal, non-professional use by natural persons (Art. 2(10)).
- Free and open-source AI systems, unless they are placed on the market as high-risk, are prohibited practices, or fall under the Art. 50 transparency rules (Art. 2(12)).
How it interacts with what you already comply with
The AI Act stacks; it does not replace.
- GDPR governs the personal data inside the system. The AI Act governs the system. Art. 10(5) is the one place they interlock explicitly: it permits processing special-category data strictly for detecting and correcting bias, with safeguards.
- DORA governs ICT risk and operational resilience for EU financial entities. Where an AI system is ICT, both apply — and their incident duties can fire together. That overlap has its own module in the Pro certification, and a dedicated tool.
- MiFID II Art. 17 and RTS 6 govern algorithmic trading. This matters because algorithmic trading appears nowhere in Annex III — a point Module 2 returns to.
- Sector law (CRR/CRD, Solvency II, PSD2) is untouched by the AI Act and continues to apply on its own terms.
Check yourself
- A vendor sells you a credit-decisioning model. You rebrand it as "YourBank Score" in your customer app. What are you? — A provider under Art. 25(1)(a). Putting your own trademark on a high-risk system makes you one, with the full Art. 8–17 set.
- Your rules engine flags transactions over €10,000 from three named countries. Is it an AI system? — No. It executes conditions a human wrote; it infers nothing. Art. 3(1) is not met.
- Your US-based model scores EU loan applicants. Your company has no EU entity. In scope? — Yes. Art. 2(1)(c): the output is used in the EU.
- Does excluding open-source software from Art. 2(12) mean an open-source high-risk system is unregulated? — No. The exemption falls away precisely when the system is high-risk, prohibited, or caught by Art. 50.
Next: Module 2 — Risk classification: the four tiers, and why most financial AI is not high-risk →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Yes, in two situations. If you place an AI system on the EU market or put it into service in the EU, you are caught as a provider regardless of where you are established. And if you are outside the EU but the OUTPUT of your system is used in the EU, Art. 2(1)(c) catches you as well. Establishment is not the test — market and output are.
No. Art. 3(1) requires a machine-based system that infers, from input, how to generate outputs, with some degree of autonomy and possible adaptiveness. A deterministic rules engine that only executes conditions a human wrote is not inferring anything and falls outside that definition. The Commission's guidelines of February 2025 confirm that simple rule-based systems are excluded.
No. They stack. The AI Act regulates the system and its lifecycle; GDPR regulates the personal data flowing through it. A compliant high-risk AI system processing personal data still needs a lawful basis, a DPIA where required, and everything else GDPR asks for.
Take compliance further with the AI Act Academy
Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.